Trust Centre

How we secure your data

A summary of the infrastructure and access controls behind the DPDP Assurance Platform, RiskSage, and the Practitioner Toolkit. This page will grow to include audit reports and a subprocessor list as they become available — for now, here's what's already in place.


Infrastructure & access controls

Data hosted in India
RBI localisation compliant
AES-256 at rest
TLS 1.3 in transit
Multi-tenant isolation
Row-level security
Immutable audit trail
SHA-256 evidence hashing
DPDP Act 2023
Privacy-by-design
Invite-only access
No self-serve risk

Regulatory frameworks our platforms map to

Modules across the three platforms are built against these frameworks so customers can evidence compliance against each one natively, without a separate mapping exercise.

RBI CyberSEBI CSCRFIRDAI 2023DPDP ActCERT-InISO 27001NIST CSF 2.0SOC 2FAIR v3.0

Vulnerability disclosure

Found a security issue in one of our products? See our vulnerability disclosure policy for how to report it and what's in scope.

Questions

For a security questionnaire, DPA, or anything not covered here, contact info@creativecyber.in.

    We use cookies and analytics (Google Analytics) to improve your experience. Under India's Digital Personal Data Protection Act, 2023, we require your consent before collecting any usage data. Privacy Policy